# Ruby script and boolean

**URL:** <https://discuss.elastic.co/t/ruby-script-and-boolean/266535>\
**Category:** Logstash\
**Created:** [March 8, 2021, 10:37am UTC](https://discuss.elastic.co/t/ruby-script-and-boolean/266535 "2021-03-08T10:37:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [March 8, 2021, 10:37am UTC](https://discuss.elastic.co/t/ruby-script-and-boolean/266535/1 "2021-03-08T10:37:20Z")

</div>

Hi there,

I have a question about the ruby filter.

I am getting logs in Json they are working quite good, but ofcourse I have inconsistence in the mapping. Usually the logs arrive with the fields

`arg0, arg1, arg,2 `

They are objects most of the times. But sometimes they are not objects so I have created a small ruby script to change the field names if they are not objects:

```auto
 ruby {
    code => "
      fields = ['arg0', 'arg1', 'arg2', 'arg3', 'arg4', 'arg5']
      fields.each do |field|
        if event.get(field) and event.get(field).class != Hash
          event.set(field, {'original_value' => event.get(field)})
        end
      end
    "
    }

```

This works quite well, but I have seen that this does not include booleans.

So when `"arg0": false, "arg1": true ` this ruby script does not work and the documents won´t be indexed because of a concrete value. I did not find a boolean class. Can anybody suggest something else I can do, except telling the developer to log properly 😉

Greetings  
Malte

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [March 8, 2021, 2:18pm UTC](https://discuss.elastic.co/t/ruby-script-and-boolean/266535/2 "2021-03-08T14:18:16Z")

</div>

Hi,

I found the issue in my script.

If there is a boolean of `"arg0":false` it will interfere with intentions if the field just exists.

> [@logger](#):
>
> ` if event.get(field) and event.get(field).class != Hash`

Here it will get a value false and skip the loop.

So I have to check it before entering the ruby filter. Or is there a nicer way?

Greetings  
Malte

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [March 9, 2021, 8:25am UTC](https://discuss.elastic.co/t/ruby-script-and-boolean/266535/3 "2021-03-09T08:25:43Z")

</div>

I have found a way to verify boolean of false.  
I found it here [stackoverflow](https://stackoverflow.com/questions/3028243/how-to-check-if-a-ruby-object-is-a-boolean)

```auto
        if event.get(field) and event.get(field).class != Hash
          event.set(field, {'original_value' => event.get(field)})
        elsif (!!event.get(field) == event.get(field)) and event.get(field).class != Hash
          event.set(field, {'original_value' => event.get(field)})
        end

```

So either it is true and no Hash or the double negative of false is "false" and this equals to "false".

Maybe someone needs this.

Greetings  
Malte

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2021, 8:26am UTC](https://discuss.elastic.co/t/ruby-script-and-boolean/266535/4 "2021-04-06T08:26:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
